Vulnerabilities (CVE)

Filtered by vendor Digitalbazaar Subscribe
Filtered by product Forge
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0122 1 Digitalbazaar 1 Forge 2022-01-12 5.8 MEDIUM 6.1 MEDIUM
forge is vulnerable to URL Redirection to Untrusted Site
CVE-2020-7720 1 Digitalbazaar 1 Forge 2022-01-12 7.5 HIGH 7.3 HIGH
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.